首页> 外国专利> Method of P2P Botnet Detection Based on Netflow Sessions

Method of P2P Botnet Detection Based on Netflow Sessions

机译:基于Netflow会话的P2P僵尸网络检测方法

摘要

The present invention detects bidirectional sessions of flows for finding P2P botnets. Unidirectional flows are combined to obtain the bidirectional sessions. The present invention is a method based on Netflow. The purpose is to highlight bidirectional sessions in a unidirectional Netflow log for determining malware activities. In addition, the present invention uses megadata for development and is implemented on MapReduce platform. Through a novel multi-layer unsupervised grouping algorithm for exploring similar bidirectional sessions, activities of the P2P botnet are analyzed. The novel grouping algorithm is coordinated with density-based clustering process to repeatedly analyze the Netflow log. Each algorithm layer extracts out a group and, in the end, collections with similar malicious behaviors are clustered out. At last, an actual Netflow log is used to prove that the present invention has a reliability up to 95%. Thus, the present invention can effectively strengthen national security information.
机译:本发明检测用于寻找P2P僵尸网络的双向流会话。组合单向流以获得双向会话。本发明是一种基于Netflow的方法。目的是在单向Netflow日志中突出显示双向会话,以确定恶意软件的活动。另外,本发明使用大数据进行开发并在MapReduce平台上实现。通过一种新颖的多层无监督分组算法来探索相似的双向会话,分析了P2P僵尸网络的活动。新颖的分组算法与基于密度的聚类过程相配合,可以重复分析Netflow日志。每个算法层都提取出一个组,最后,将具有类似恶意行为的集合聚类。最后,使用实际的Netflow日志来证明本发明具有高达95%的可靠性。因此,本发明可以有效地增强国家安全信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号